Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2016-3097: 1322747 – (CVE-2016-3097) CVE-2016-3097 spacewalk-java: Multiple XSS flaws

Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.

CVE
#xss#vulnerability#web#linux#red_hat#java

Bug 1322747 (CVE-2016-3097) - CVE-2016-3097 spacewalk-java: Multiple XSS flaws

Summary: CVE-2016-3097 spacewalk-java: Multiple XSS flaws

Keywords:

Status:

CLOSED ERRATA

Alias:

CVE-2016-3097

Product:

Security Response

Classification:

Other

Component:

vulnerability

Sub Component:

Version:

unspecified

Hardware:

All

OS:

Linux

Priority:

medium

Severity:

medium

Target Milestone:

Assignee:

Red Hat Product Security

QA Contact:

Docs Contact:

URL:

Whiteboard:

Depends On:

1322710

Blocks:

1322748

TreeView+

depends on / blocked

Reported:

2016-03-31 09:07 UTC by Adam Mariš

Modified:

2021-02-17 04:07 UTC (History)

CC List:

7 users (show)

Fixed In Version:

Doc Type:

Bug Fix

Doc Text:

A stored cross-site scripting (XSS) flaw was found in the way spacewalk-java displayed group names. An attacker can embed HTML and Javascript in the values for group names in Satellite, allowing them to inject malicious content into the web page that is then displayed when viewing the snapshot data.

Clone Of:

Environment:

Last Closed:

2016-07-26 09:27:01 UTC

Attachments

(Terms of Use)

Add an attachment (proposed patch, testcase, etc.)

Links

System

ID

Private

Priority

Status

Summary

Last Updated

Red Hat Product Errata

RHSA-2016:1484

0

normal

SHIPPED_LIVE

Moderate: spacewalk-java security and bug fix update

2016-07-26 11:45:55 UTC

Description Adam Mariš 2016-03-31 09:07:51 UTC

Group name is not properly escaped allowing XSS

An XSS vulnerability was found in WebUI when creating group with HTML via SSM or API and checking snapshot with this group join/leave.

Product bug:

https://bugzilla.redhat.com/show_bug.cgi?id=1322710

Comment 1 Adam Mariš 2016-03-31 09:08:01 UTC

Acknowledgments:

Name: Jan Hutař (Red Hat)

Comment 2 errata-xmlrpc 2016-07-26 07:46:46 UTC

This issue has been addressed in the following products:

Red Hat Satellite 5.7

Via RHSA-2016:1484 https://rhn.redhat.com/errata/RHSA-2016-1484.html

Note You need to log in before you can comment on or make changes to this bug.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907